ZeroHour

CVE-2022-26258

KEV PoC ×2large

Unauthenticated Remote Command Execution in D-Link DIR-820L Router

CISA: D-Link DIR-820L Remote Code Execution Vulnerability

CVSS 3.1
9.8 critical
EPSS
92%p100
Published
()
KEV added
AI analysis

CVE-2022-26258 is an unauthenticated OS command injection (CWE-78) in D-Link DIR-820L router firmware, confirmed in version 1.05B03, reachable through the HTTP POST 'get set ccp' command interface. A remote attacker with no credentials and no user interaction can send a crafted HTTP POST request to this endpoint to execute arbitrary operating-system commands on the device. Successful exploitation yields full control of the router, providing a foothold for traffic interception, device enlistment into botnets, and lateral access to the home or small-office network behind it. Only users running the affected D-Link DIR-820L, an end-of-life consumer router, are affected, and no fixed firmware version is provided in the available data. Exploitation is confirmed in the wild: CISA added the flaw to its Known Exploited Vulnerabilities Catalog on 2022-09-08 with a 92% EPSS score, and public reporting describes the Mirai-variant MooBot botnet targeting vulnerable D-Link devices.

What to do: Because the DIR-820L is end-of-life and CISA's required action is to disconnect it if still in use, replace or retire the router; check the model and firmware version on the device's status/admin page (1.05B03 is confirmed vulnerable). If replacement is not immediate, disconnect the device from the internet or restrict exposure with firewall rules so the HTTP management interface is not reachable by untrusted hosts, and watch for Mirai-variant (MooBot) botnet traffic patterns. No fixed firmware version is provided in the available data, so upgrading alone is not a documented remedy.

Affected
D-Link DIR-820L router firmware1.05B03 confirmed affected; the product is end-of-life and no fixed version is specified in the available data
Estimated exposure
large≈10,000–100,000 internet-exposed DIR-820L devices (order-of-magnitude estimate; a widely sold but end-of-life consumer router) — Estimated from the DIR-820L's broad historical consumer retail distribution and public internet scans that consistently show tens of thousands of exposed D-Link DIR-series routers, tempered by the device's end-of-life status, which means…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

D-Link DIR-820L 1.05B03 was discovered to contain remote command execution (RCE) vulnerability via HTTP POST to get set ccp.

CISA Known Exploited Vulnerability
Affected
D-Link DIR-820L
Required action
The impacted product is end-of-life and should be disconnected if still in use.
Due date
Ransomware use
Unknown
Vendors
dlink
Products
dir-820l firmware
Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

Mirai Variant MooBot Targeting D

Unit 42 observed the MooBot Mirai variant exploiting four D-Link vulnerabilities to compromise unpatched routers for use in DDoS attacks.

Unit 42 captured attacks exploiting four D-Link remote code execution vulnerabilities: CVE-2015-2051, CVE-2018-6530, CVE-2022-26258, and CVE-2022-28958, with three rated critical at CVSS 9.8. The exploits download the MooBot malware, a Mirai botnet variant, from infrastructure at 159.203.15.179 via wget. Compromised devices fall under full attacker control and can be used for distributed denial-of-service attacks. D-Link has published bulletins for all four flaws, but unpatched devices remain exposed.

Palo Alto Unit 42 · 29d agoMalware in the wildCVE-2015-2051CVE-2018-6530CVE-2022-26258+1 CVEs